A significant leak of sensitive information affects users globally, revealing login details from major online services.
A massive data breach has come to light, affecting approximately 184 million individuals worldwide.
The breach involves user credentials, including usernames and passwords for accounts across various platforms such as Google, Microsoft, Apple, Meta (including
Facebook and Instagram), Roblox, and Snapchat.
The data was found in an open database that lacked encryption, making it accessible to anyone on the internet.
Cybersecurity expert Jeremiah Fowler reported that the database contains precisely 184,162,718 unique combinations of usernames and passwords, all compiled in a file size of 47.42 GB. The exposed data not only encompasses login credentials for social media accounts but also includes sensitive access information for banking accounts, emails, applications, services, and governmental health portals.
The most likely source of the exposed information is attributed to a malicious 'infostealer' program, details of which remain unclear.
Such malware is designed to infiltrate victims' computers and steal sensitive information, including access credentials stored within web browsers, email clients, or messaging applications.
Certain variants of this malware are capable of extracting data from autofill functions in browsers, internet cookies, or digital wallets for cryptocurrency.
Fowler confirmed the authenticity of the data through personal verification, stating that the usernames and passwords in the discovered database are indeed valid and active.
He emphasized basic protective measures to mitigate potential attacks that could arise once such data is in the hands of malicious actors.
These recommendations include regularly updating passwords, employing two-factor authentication wherever possible, selecting unique and complex passwords, and utilizing password managers alongside antivirus solutions.